28th May 2018

A week in security (May 21 – May 27)

Last week we told you about a Mac cryptominer using XMRig, an overview of Dreamcast related scams, part 1 of decoding Emotet, and what to do about bad coding habits that die hard. We also published the results of our second CrackMe contest. Other news How a pioneer of machine learning became one of its sharpest critics. (Source: The Atlantic) The man who cracked the lottery. Spoiler: it was an inside job. (Source: The New York Times Magazine) New Spectre (variant 4) CPU flaw discovered —Intel, ARM, AMD affected (Source: The Hacker News) Amazon urged not to sell facial recognition tool to police. (Source: ABC News) Does the Facebook app even spy on those who don’t have an account? (Source: The Register) FBI stats: email fraud still #1 cybercrime. (Source: MailGuard Blog ) Brain Food spam botnet malware found on thousands of websites. (Source: SCMagazine) Amazon Alexa Security – How to stop hacks on voice assistants. (Source: Forbes) Necurs delivering flawed Ammy RAT via IQY Excel Web ..
25th May 2018

5 malware attacks making the news | Avast

BMWs at risk of hacking BMW is in the process of issuing security patches to drivers of its 2017 i3, 2016 X1 and 525Li, and 2012 730Li. The patches will cover fourteen newly-discovered vulnerabilities, four of which can be triggered only through physical connection to the car computer systems, while another four require USB connection to the car. The remaining six vulnerabilities can be exploited remotely. A diligent cybercriminal can gain access to the cars’ infotainment systems, T-Box components, and UDS communication. In light of the findings, BMW has embraced the value of third-party cybersecurity research, and they are working on fixes.
22nd May 2018

Avast Mobile Security for Android put to the test | Avast

Cybercriminals have caught on. Our mobile devices are where it’s at. Personal info, bank accounts, passwords, important contacts — all this data is on our phones. And data today is more valuable than gold, which makes smartphones the new motherload. Realizing “there’s gold in them thar cells!” the cyber-underground targeted devices more than ever over the past year.
21st May 2018

A week in security (May 14 – May 20)

Last week, we looked at the deluge of incoming policies caused by GDPR, tackled Adobe Reader zero days, and ran through some iPhone security tips. We also caught some helpline scammers in the act, explored advergaming, got our Senate Bill game face on, and deep dived into Drupal vulnerabilities. Other news Mining apps in Snaps store controversy (Source: The Register) Man identified in spy tools leak (Source: Washington Post) Facial recognition technology under fire (Source: Big Brother Watch) Phishers increasingly targeting SaaS/cloud storage (Source: Help Net Security) Yet another Facebook leak (Source: New Scientist) Signal caught by HTML tag injection (Source: Ivan Barerra Oro Blog) iOS has a ZipperDown problem (Source: Zipperdown(dot)org) Avoid this ICO scam (Source: Naked Security) Avoiding phishing with machine learning (Source: Business dot com) There’s always time for some more Mac malware (Source: LifeHacker) Stay safe, everyone! The post A week in security (May 14 – May 20)..
18th May 2018

Victory for net neutrality and trouble for Telegram Messenger | Avast

Dangerous PDF exploit combines two vulnerabilities Fortunately, patches exist for both vulnerabilities in question, but if an unpatched Windows system suffers infection from this PDF exploit, all bets are off.